Commit Graph
764 Commits
Author SHA1 Message Date
Kenneth Skovhede 07cd39af34 Add support for managed TLS
This PR adds support for generating a self-signed CA and then using that CA to generate TLS certificates.

A new tool `duplicati-configure` / `Duplicati.CommandLine.ConfigureTool.exe` is added to manage the certificates.  The tool saves the configuration in the database and is meant to run with elevated privileges for the initial CA installation.

The option `--configure-https` can be added to server/trayicon, and if the process has permissions, this will automatically install the CA certificate.

If a CA is configured, the server will automatically issue, renew and use a TLS certificate.

With this setup, the TLS is opt-in, but once the flow is well tested, we can switch it to opt-out.
2026-03-01 11:33:05 +01:00
Kenneth Skovhede 7a993421f2 Fixed bug with scheme detection
This PR fixes a reported issue with strings that are less than 3 characters.

This is unlikely, but happens if the code tries to get the scheme of a path, like `/a` or `/`.

The updated logic returns the scheme if one exists, and it is less than 15 characters (to avoid leaking sensitive information).
2026-02-07 16:13:52 +01:00
Kenneth Skovhede 05ea1dfafe Check free temporary space
This PR adds checks for free temporary space when starting the server and when restoring.

On systems that have limited space in the temp folder a warning will now be shown.

This is intended to capture issues on some Docker systems where /tmp is mounted in memory instead of being disk backed.

It will also detect the issue on other systems that are space constrained.
2026-02-06 10:37:27 +01:00
Kenneth Skovhede 0f806c1a3a Improve WebDAV SSL certs
This PR now checks for the SSL certificate and the UI will offer to pin the certificate if this is not a trusted certificate.

Also, the sourceproviders and restoredestinationproviders now actually invoke the `Test` method when being tested.
2026-02-03 14:57:11 +01:00
Kenneth Skovhede ca7dff57f3 Updated restore flow to use the IRestoreDestinationProvider interface for accessing files 2026-01-14 10:11:24 +01:00
Kenneth Skovhede 1523f730e3 Added support for storing metadata in the database 2026-01-14 10:01:20 +01:00
Kenneth Skovhede 83779a9486 Minor fixes
- Added Cloudflare to list of known S3 provider domains.
- Removed AWS specific naming on the help texts.
- Fixed an edge case where calculating how many files to test with an empty list would crash
- Fixed a bug with getting a safe display url for very short urls
2026-01-06 09:48:23 +01:00
Kenneth Skovhede d7ab1b03ac Merge remote-tracking branch 'origin/HEAD' into feature/duplicati-storage-backend
Streamlined the use of SharedRemoteOperation
2025-12-10 15:33:35 +01:00
Kenneth Skovhede 5cfa9724d7 Added support for loading remote backup names in Duplicati Storage 2025-12-09 21:17:01 +01:00
Kenneth Skovhede 588cec8aa6 More robustness for Pass 2025-12-08 12:05:24 +01:00
Kenneth Skovhede 6d9826df06 Initial implementation of write-support for SecretProviders
This updates the MacOS secret provider to use PInvoke for a more stable API than the secrets tool that was used before.
2025-11-30 23:01:57 +01:00
Kenneth Skovhede ef649f3926 Updated reporting to include more details
This PR updates the reports sent to include a more detailed OS version string, similar to what is used by the usagereporter and systeminfo call.

It also reports parts of the destination hostname, if using S3 and the host is a known public cloud. This is done to avoid leaking internal hostnames or actual bucket names, but still provide some way to identify what storage service is used.
2025-11-28 12:04:47 +01:00
Kenneth Skovhede e1b9015a85 Added support for exclusion of files based on xattrs
This PR adds detection of exclusion attributes on files and folders. If a file or folder has an exclusion extended attribute, the file or folder is excluded from the backup.

The option `--disable-backup-exclusion-xattr` can be used to revert to the previous behavior where the xattrs were not checked.

This has the biggest impact on MacOS where it will not perform like other backup software and avoid files that are marked as excluded from backup.

This fixes #6393
2025-11-21 10:59:28 +01:00
Kenneth Skovhede 5620c083d8 Fixed some 9.0.6 refs 2025-11-14 17:08:19 +01:00
Kenneth Skovhede 43d38efdd3 Fixed remaining warnings 2025-11-14 16:09:05 +01:00
Kenneth Skovhede 178440f869 Fixed a number of warnings 2025-11-14 16:00:06 +01:00
Kenneth Skovhede 1ea74a3c63 Updated to .NET10 2025-11-14 15:05:39 +01:00
Kenneth Skovhede 012aeed7de Add dynamic streaming toggle
This PR adds a dynamic property so a backend can signal if it supports streaming, based on the settings.

This is currently used for the File backend, so that toggling `--use-move-for-put` will disable streaming on the backend instead of relying on the `--disable-streaming-transfers` flag.
2025-11-03 12:48:37 +01:00
Kenneth Skovhede 4b3ccde3f7 Fixed parsing enum flags
This fixes #6574
2025-10-31 11:38:06 +01:00
Kenneth Skovhede 1f41c7af12 Moved to JsonSignature library
Code that was previously embedded in th Duplicati.Library.Utility is now in its own library.
2025-10-08 10:11:57 +02:00
Kenneth Skovhede 39cca5c24f Simplified calling code to not rely on extension methods 2025-09-25 11:33:56 +02:00
Kenneth Skovhede 230d80642a Fixed invariant formatting helpers
This fixes an issue with formatting for invariant values that was caused by incrorrect function overload selection.

To avoid future issues, the two similar functions have been renamed to clarify what they are working for.
2025-09-25 11:14:54 +02:00
Kenneth SkovhedeandGitHub 360253c062 Merge branch 'master' into feature/hyperv-and-mssql-sources 2025-09-12 09:07:04 +02:00
Carl Johnsen 7670ea9a58 Ensured that all values that are passed to interpolation strings have been passed through FormatInvariant to prevent SQLite errors related to string formatting cultures. 2025-09-05 14:11:05 +02:00
Carl Johnsen 1a5fef36d7 Removed whitespace 2025-09-05 14:07:58 +02:00
Carl Johnsen b3fe276a13 Ensured that all temporary tables uset the same type of generated guid name 2025-09-05 14:06:55 +02:00
Svend Roperos c1e22faa03 fix: make string.Split calls explicit to resolve ambiguous overloads 2025-09-04 20:14:52 +02:00
Kenneth Skovhede a673bd0fab Fixed pre-calc SHA256 on AWS S3
This fixes pre-calculating the SHA256 hash for AWS SDK requests to S3.
This fixes an issue where a throttled stream would not be throttled correctly, because the AWS library would read the throttled stream twice (once for hashing, and once for transmitting).

To ensure compatibility with Wasabi S3, the hash is also lowercased.
2025-08-15 10:59:38 +02:00
Kenneth SkovhedeandGitHub ba7bee397c Merge branch 'master' into 0nbrsf-codex/find-outdated-packages 2025-08-07 10:48:59 +02:00
Kenneth Skovhede 9a97562a81 Added the Uri changes 2025-08-07 08:08:56 +02:00
Kenneth Skovhede 80945398fc Fixed nullability for Uri class 2025-07-15 13:33:16 +02:00
Kenneth Skovhede 9c6c52fbbb Fixed a null error 2025-07-15 13:29:40 +02:00
Kenneth Skovhede 19af340d49 Added support for correct parsing of Windows paths as URLs 2025-07-15 13:04:50 +02:00
Kenneth Skovhede aa42734cf8 Dots in url hostname
This fixes the encoding of hostnames with `.` characters in them. Without this fix, the hostname would be encoded making it impossible to use regular DNS hostnames.
2025-07-15 10:58:36 +02:00
Kenneth Skovhede 79811dc4c6 Added correct encode and decode of paths in urls.
The URLs passed to the custom URL parser were not decoding the path part, but passing it directly. This caused problems if the input was correctly URL encoded.

The updated code now correctly decodes the hostname+path parts, and encodes them again.
2025-07-11 12:08:04 +02:00
Kenneth SkovhedeandGitHub 30cb3ae9a3 Merge pull request #6383 from duplicati/feature/drop-sebackupprivilege
Update permission check to drop privilege
2025-07-01 15:18:06 +02:00
Kenneth Skovhede 9d8f426c99 Fixed crashs in debug mode
This fixes the callstack walker to handle cases where the call frame has no assembly.
The code is only compiled for debug builds.
2025-07-01 11:47:30 +02:00
Kenneth Skovhede 9eb2ceada5 Update permission check to drop privilege
This PR adjusts the check for SeBackupPrivilege and unassigns the privilege after testing if it could be enabled.

This fixes #6317
2025-07-01 11:45:29 +02:00
Kenneth Skovhede 819af9e66f Update .NET dependencies 2025-06-24 07:51:26 +02:00
Kenneth SkovhedeandGitHub 9dfe618444 Merge pull request #6338 from duplicati/feature/detect-erperm-errors
Detect EPERM on mac/Linux
2025-06-12 22:25:54 +02:00
Kenneth Skovhede af82ed3a49 Detect EPERM on mac/Linux
This PR updates the check for permission denied to include EPERM and EACCES on macOS/Linux.
2025-06-12 13:36:53 +02:00
Kenneth Skovhede 35058d333e Update handling of alternate OAuth url
This PR removes the `OAuthContextSettings` class, and makes the `--oauth-url` option available on each backend that uses it, so it can be configured as part of the destination.

To assemble everything related to configuring OAuth, the code was moved to the `AuthIdOptionsHelper`, such that the usage can be shared between implementations.

This PR also adds the option to set the default OAuth url from the environment variable `DUPLICATI_OAUTH_SERVICE`.

The server can then be set in the following locations (most important last):
- Environment variable
- Server-wide advanced settings
- Backup job advanced settings (or commandline)
- Destination url
2025-06-11 09:27:40 +02:00
Kenneth Skovhede c8b9fb5c73 Websocket subscriptions
This PR adds the ability to subscribe to messages over a websocket.

To prevent polling data, the server can now push messages through the websocket, so the client can instantly update when new data is available.

The change is backwards compatible, still serving the status updates over the socket. If the client is providing the authentication token, it is auto-subscried to the legacy status message.

If the client is using the new authentication message, it needs to subscribe to get the status updates (and any other services it needs).

The event system has been extended to support new, and more accurate, events. This is the first step towards removing the general status update and the long-poll mechanism.

This also re-introduces the blocking marker, so the client can know if the operation is halted due to too many pending transfers.

Some endpoints have been moved to service implementations, to allow serving the exact same data from both endpoints and websocket.

This PR also updates the way the progress is handled, so that all transfers are returned to the client, and the transfer speeds for each transfer is calculated based on a small sample buffer, so the values are more accurate even if the program is paused during transfers.
2025-05-27 12:13:07 +02:00
Kenneth Skovhede 6a42613f70 Fixed passing the FolderMissingException to the caller for triggering the autocreate 2025-05-24 15:34:38 +02:00
Kenneth Skovhede 0eef7ec49b Final removal of AsyncHttpRequest. 2025-05-24 13:55:19 +02:00
Kenneth Skovhede 6031b4de8b Update Test method to check for write permissions
This PR moves the check from the FTP backend into shared code, so all backends will now check for read/write permissions when using the "Test" button.

For situations where write permissions are not required (like restore or verify) there is a flag on the v2 API that indicates if the connection was established, so the UI can show a message suggesting that it is possible to proceed, if the current UI operation does not require write permissions.

This fixes #2473
2025-05-21 17:19:27 +02:00
Kenneth Skovhede 8fb37cb6f5 Fixed query to ensure privilege is enabled.
Removed wrong check.
2025-05-20 17:34:05 +02:00
Kenneth Skovhede ded55740de Set VSS to Auto if user has permissions
If th user has the SeBackupPrivilege, set the default snapshot policy to `Auto` and otherwise use `Off` (the current default).

This ensures that if the process is running with the correct permissions, there will be fewer warnings.

This only changes the default value on Windows.

This fixes #2833
2025-05-20 16:53:11 +02:00
Kenneth Skovhede 1cfacca794 Enabled nullable for FilterExpression and Options
This adds nullability to FilterExpression and Options.
It also updates almost all properties in Options to use a common format that enforces uniform parsing of the values.

A few options have been updates to have the default values specified as a constant, to avoid replicating the value in two places.
2025-05-20 14:36:39 +02:00
Kenneth Skovhede ef631a1199 Added feature to suppress warnings
This PR adds the option to suppress warnings by their log id. Warning IDs that are supplied to `--suppress-warnings` will be converted to information messages before being logged.

If a specific warning is disabled, such as `CompressionReadErrorFallback`, this will then no longer count as a warning for the job, and the log file will see the warning as an information message.

This PR also adds two simpler filter options that makes it possible to filter log messages by supplying the log IDs. This can already be achieved with log filters, but the ID filter is a bit simpler to apply, as you only need to know the ID.

Finally, this PR also adds common logging for errors in the categories:
- Permission denied, id = `PermissionDenied`
- File locked, id = `FileLocked`
- Path not found, id = `PathNotFound`
- Path too long, id = `PathTooLong`

These new log ids makes it simpler to ignore warnings about locked or inaccesible files.
2025-05-20 14:26:10 +02:00